|
841
|
8.8 |
HIGH
Network
|
-
|
-
|
BuddyPress Xprofile Custom Fields Type 2.6.3 contains a remote code execution vulnerability that allows authenticated users to delete arbitrary files by manipulating unescaped POST parameters. Attack…
|
CWE-22
Path Traversal
|
CVE-2018-25308
|
2026-05-1 00:44 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
842
|
6.2 |
MEDIUM
Local
|
-
|
-
|
SysGauge 4.5.18 contains a buffer overflow vulnerability in the proxy configuration handler that allows local attackers to cause a denial of service by supplying an oversized string. Attackers can in…
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25313
|
2026-05-1 00:44 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
843
|
7.5 |
HIGH
Network
|
-
|
-
|
Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence.
Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both hea…
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-40560
|
2026-05-1 00:13 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
844
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vu…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-23773
|
2026-05-1 00:13 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
845
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
|
CWE-601
Open Redirect
|
CVE-2026-42525
|
2026-05-1 00:13 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
846
|
- |
|
-
|
-
|
Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to tri…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-2810
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
847
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoDB server.
This issue affects all MongoDB Server v8.2 versions, all MongoDB Serv…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-6914
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
848
|
6.3 |
MEDIUM
Network
|
-
|
-
|
An authorization flaw in the user management command could allow an authenticated user to make limited changes to authentication-related data associated with another user account. This could affect h…
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-6915
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
849
|
4.8 |
MEDIUM
Network
|
-
|
-
|
wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpos…
|
CWE-20
Improper Input Validation
|
CVE-2026-1858
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
850
|
7.4 |
HIGH
Network
|
-
|
-
|
In JetBrains IntelliJ IDEA before 2024.3.7.1,
2025.1.7.1,
2025.2.6.2,
2025.3.4.1,
2026.1.1 reading arbitrary local files was possible via built-in web server
|
CWE-59
Link Following
|
CVE-2026-41882
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|